Ostap malware analysis (Backswap dropper)
ID: dced8a03-c630-58b1-87b6-ccca79a8d982
STIX ID: report--dced8a03-c630-58b1-87b6-ccca79a8d982
Feed Name: CERT Polska
Executive summary: This report analyzes the Ostap JSE/JScript dropper campaigns (notably active in Poland) that deliver banking malware families and have evolved from simple downloaders into persistent distribution botnets. Key findings include delivery via ACE archives disguised with a .rar extension, large obfuscated JSE payloads, POST-based C2 sending system and process info, configurable execution headers (e.g. you_god_damn_right), persistence via Startup and self-update, sandbox/analysis detection, and destructive propagation to removable media; the report also lists characteristic URL/parameter patterns and sample notes.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
